PT-2026-79333 · Apache · Cloudstack

·

CVE-2026-68745

·

Published

2026-08-21

·

Updated

2026-08-21

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache CloudStack version 4.20.3.0 Apache CloudStack version 4.22.1.0
Description Certificate validation failures in SAML authentication allow a malicious agent to forge a SAML response to the management server. To exploit this, an attacker must spoof the IP address of the Identity Provider (IdP) or register a URL of their choice in the management server, enabling unauthorized login using forged signatures.
Recommendations Upgrade version 4.20.3.0 to 4.20.3.1 or above. Upgrade version 4.22.1.0 to 4.22.1.1 or above.

Exploit

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-68745

Affected Products

Cloudstack